Skip to content

Releases: projectdiscovery/nuclei-templates

v9.5.1

01 Jun 09:14
Compare
Choose a tag to compare

🔥 Highlights of this release:

✅ [CVE-2023-32243] WordPress Elementor Lite 5.7.1 - Arbitrary Password Reset (@dhiyaneshdk) [critical]
✅ [CVE-2023-29923] PowerJob <=4.3.2 - Unauthenticated Access (@For3stCo1d) [medium]
✅ [CVE-2023-25717] Ruckus Wireless Admin - Remote Code Execution (@parthmalhotra,@pdresearch) [critical]
✅ [CVE-2023-2825] GitLab 16.0.0 - Path Traversal (@dhiyaneshdk,@rootxharsh,@iamnoooob,@pdresearch) [critical]
✅ [CVE-2023-2732] MStore API <= 3.9.2 - Authentication Bypass (@dhiyaneshdk) [critical]
✅ [CVE-2021-39165] Cachet <=2.3.18 - SQL Injection (@tess) [high]
✅ [CVE-2020-29583] ZyXel USG - Hardcoded Credentials (@canberbamber) [critical]
✅ [CVE-2020-1956] Apache Kylin 3.0.1 - Command Injection (@iamnoooob,@rootxharsh,@pdresearch) [high]
✅ [CVE-2016-3510] Oracle WebLogic Server - Remote Code Execution (@iamnoooob,@rootxharsh,@pdresearch) [critical]

What's Changed

New Templates Added: 56
New CVEs Added: 23

New Contributors

Full Changelog: v9.5.0...v9.5.1

Nuclei Templates v9.5.0 (breaking changes)

11 May 15:32
Compare
Choose a tag to compare

Release Highlight:

  1. Nuclei Templates Refactoring: organized and categorized directory structure for improved management of nuclei templates.
  2. Enhanced CVE Templates: more comprehensive vulnerability analysis with added information like CPE and EPSS Score.
  3. Template Metadata: auto-generated max-request counter to each template, allowing easy filtering and visibility of maximum request.
  4. Log4j Templates Update: updated templates addressing potential false positives related to Log4j.
  5. KEV & Trending CVEs: a curated selection of noteworthy Known Exploited Vulnerabilities (KEV) and Trending CVEs, highlighted with 🔥.

See nuclei-templates v9.5.0, projectdiscovery/nuclei#3648, https://blog.projectdiscovery.io/nuclei-template-v9-5-0-update/ for more details.


New Templates Added : 61

New Contributors

Full Changelog: v9.4.3...v9.4.4

v9.4.3

24 Apr 04:52
Compare
Choose a tag to compare

What's Changed

New Templates Added: 55

New Contributors

Full Changelog: v9.4.2...v9.4.3

v9.4.2

09 Apr 03:16
Compare
Choose a tag to compare

What's Changed

New Templates Added: 78

New Contributors

Full Changelog: v9.4.1...v9.4.2

v9.4.1

27 Mar 06:41
Compare
Choose a tag to compare

What's Changed

New Templates Added : 69

New Contributors

Full Changelog: v9.4.0...v9.4.1

v9.4.0

18 Mar 09:14
Compare
Choose a tag to compare

What's Changed

New Templates Added: 65

New Contributors

Full Changelog: v9.3.9...v9.4.0

v9.3.9

10 Mar 18:42
Compare
Choose a tag to compare

What's Changed

New Templates Added : 61

New Contributors

Full Changelog: v9.3.8...v9.3.9

v9.3.8 [Treasure Trove of OSINT Templates]

27 Feb 06:13
Compare
Choose a tag to compare

What's Changed

Upgrade Your OSINT Game with Comprehensive OSINT Nuclei Templates

New Templates Added : 656

[+] OSINT Nuclei Templates 🔥

Read more

v9.3.7

10 Feb 16:05
Compare
Choose a tag to compare

What's Changed

New Templates Added : 58

Full Changelog: v9.3.6...v9.3.7

v9.3.6

27 Jan 17:10
Compare
Choose a tag to compare

What's Changed

New Templates Added : 31

  • cves/2022/CVE-2022-39195.yaml by @arafatansari
  • cves/2022/CVE-2022-32429.yaml by @theabhinavgaur
  • cves/2022/CVE-2022-1168.yaml by @akincibor
  • cves/2017/CVE-2017-1000163.yaml by @0x_Akoko
  • vulnerabilities/other/academy-lms-xss.yaml by @arafatansari
  • vulnerabilities/other/slims-xss.yaml by @arafatansari
  • vulnerabilities/other/sound4-file-disclosure.yaml by @arafatansari
  • vulnerabilities/other/tikiwiki-xss.yaml by @arafatansari
  • vulnerabilities/vmware/vmware-cloud-xss.yaml by tess
  • misconfiguration/esphome-dashboard.yaml by @ritikchaddha
  • misconfiguration/installer/nagiosxi-installer.yaml by @ritikchaddha
  • misconfiguration/rethinkdb-admin-console.yaml by tess
  • misconfiguration/sound4-directory-listing.yaml by @arafatansari
  • misconfiguration/syncthing-dashboard.yaml by @fabaff
  • misconfiguration/webalizer-statistics.yaml by @0x_Akoko
  • exposures/configs/cypress-web-config.yaml by tess
  • exposed-panels/completeview-web-panel.yaml by tess
  • exposed-panels/connect-box-login.yaml by @fabaff
  • exposed-panels/esphome-panel.yaml by @fabaff
  • exposed-panels/fortinet/fortios-management-panel.yaml by @mbmy
  • exposed-panels/mystrom-panel.yaml by @fabaff
  • exposed-panels/pulsar-admin-console.yaml by @ritikchaddha
  • exposed-panels/pulsar-adminui-panel.yaml by @ritikchaddha
  • exposed-panels/pulsar360-admin-panel.yaml by tess
  • exposed-panels/saltstack-config-panel.yaml by @pussycat0x
  • exposed-panels/sqlbuddy-panel.yaml by nullfuzz
  • network/detection/teamspeak3-detect by @pussycat0x
  • file/android/deep-link-detect.yaml by Hardik-Solanki
  • headless/headless-open-redirect.yaml by @theamanrawat
  • miscellaneous/exposed-file-upload-form.yaml by @geeknik
  • technologies/default-lighttpd-placeholder-page.yaml by @idealphase

New Contributors

Full Changelog: v9.3.5...v9.3.6